May 17, 2026
Linux kernel sets rules for AI-assisted security reports
Short plain-text reports, verifiable impact, a tested reproducer shared on request and a tested fix with a Fixes: tag. Torvalds calls the private security list almost unmanageable.
In May 2026 the kernel merged new documentation, written by Willy Tarreau and acked by Greg Kroah-Hartman, on responsible use of AI to find bugs. The security list had gone from two or three reports a week to five to ten a day, many of them duplicates found with the same tools.
The rules ask reporters to put a clear summary first and keep reports short; convert them to plain text without Markdown; stick to verifiable impact under the kernel's threat model; always provide and test a reproducer, sharing it only on maintainers' request; and propose a tested fix with a Fixes: tag naming the commit that introduced the bug.
Linus Torvalds added that AI-detected bugs are by definition not secret and should go directly to maintainers. These rules shaped ossscanner.org: concise reports, verification before output, a patch and introducing commit for every finding, and reproducers revealed only to maintainers.
Sources
Want to see what an AI audit finds in your project? Quick scans are free and take a few minutes.
Scan a repository